DATABASE All ShinyHunters Leaks (WORKING) 2026

#1
Some of the links I posted from ShinyHunters like Lacoste, Zara, Amazon Owned One Medical and others are dead due to ShinyHunters download server automatically changing IP's. 

Here's a link to their website and backup mirrors included for each leak on their site. I'm not affilated with ShinyHunters or any activity related to them. Everything I post on Spear is public information that anyone can find.

About: ShinyHunters is a financially motivated data-theft and extortion group active since 2020, responsible for high-profile breaches including Ticketmaster (via Snowflake) and PowerSchool; by 2025 they launched a RaaS offering called "shinysp1d3r," and in August 2025 French authorities arrested four members. ShinyHunters has breached 132 companies and counting.

Vulnerabilities Exploited (3): 
Oracle

Oracle E-Business Suite (EBS)
CVE-2025-61882

Cisco

Cisco Unified Communications
CVE-2026-20045

Snowflake

Snowflake (credential stuffing / no MFA)
OAuth Abuse 

TTPs Matrix: 
Unsecured Credentials: Private Keys

Use Alternate Authentication Material: Application Access Token
Data from Information Repositories
Exfiltration Over Web Service
Data Encrypted for Impact
Phishing for Information: Spearphishing Attachment 
Phishing: Spearphishing Voice (Vishing)
 

ShinyHunters Leaks Site: 
Hidden Content
You must register or login to view this content.
Reply
#3
(07-25-2026, 03:42 AM)aqua Wrote: Some of the links I posted from ShinyHunters like Lacoste, Zara, Amazon Owned One Medical and others are dead due to ShinyHunters download server automatically changing IP's. 

Here's a link to their website and backup mirrors included for each leak on their site. I'm not affilated with ShinyHunters or any activity related to them. Everything I post on Spear is public information that anyone can find.

About: ShinyHunters is a financially motivated data-theft and extortion group active since 2020, responsible for high-profile breaches including Ticketmaster (via Snowflake) and PowerSchool; by 2025 they launched a RaaS offering called "shinysp1d3r," and in August 2025 French authorities arrested four members. ShinyHunters has breached 132 companies and counting.

Vulnerabilities Exploited (3): 
Oracle

Oracle E-Business Suite (EBS)
CVE-2025-61882

Cisco

Cisco Unified Communications
CVE-2026-20045

Snowflake

Snowflake (credential stuffing / no MFA)
OAuth Abuse 

TTPs Matrix: 
Unsecured Credentials: Private Keys

Use Alternate Authentication Material: Application Access Token
Data from Information Repositories
Exfiltration Over Web Service
Data Encrypted for Impact
Phishing for Information: Spearphishing Attachment 
Phishing: Spearphishing Voice (Vishing)
 

ShinyHunters Leaks Site: 

thank you
This account is currently banned.
Ban Length: Permanent
Ban Reason: Leeching | https://spear.cx/Forum-Ban-Appeals if you feel this is incorrect.
Reply
#4
thank youuuuuuuuuuuuuuuuuuuuuuuuuuuuu
Reply
#5
(07-25-2026, 03:42 AM)aqua Wrote: Some of the links I posted from ShinyHunters like Lacoste, Zara, Amazon Owned One Medical and others are dead due to ShinyHunters download server automatically changing IP's. 

Here's a link to their website and backup mirrors included for each leak on their site. I'm not affilated with ShinyHunters or any activity related to them. Everything I post on Spear is public information that anyone can find.

About: ShinyHunters is a financially motivated data-theft and extortion group active since 2020, responsible for high-profile breaches including Ticketmaster (via Snowflake) and PowerSchool; by 2025 they launched a RaaS offering called "shinysp1d3r," and in August 2025 French authorities arrested four members. ShinyHunters has breached 132 companies and counting.

Vulnerabilities Exploited (3): 
Oracle

Oracle E-Business Suite (EBS)
CVE-2025-61882

Cisco

Cisco Unified Communications
CVE-2026-20045

Snowflake

Snowflake (credential stuffing / no MFA)
OAuth Abuse 

TTPs Matrix: 
Unsecured Credentials: Private Keys

Use Alternate Authentication Material: Application Access Token
Data from Information Repositories
Exfiltration Over Web Service
Data Encrypted for Impact
Phishing for Information: Spearphishing Attachment 
Phishing: Spearphishing Voice (Vishing)
 

ShinyHunters Leaks Site: 
woah this is crazy if this is like fr fr
Reply
#6
thank you for the data, keep doing this
Reply



Recently Browsing 4 Guest(s)